Cybersecurity

SonicWall Warns of Zero-Day Exploitation in SMA1000 Devices

SonicWall confirmed that attackers are exploiting two zero-day vulnerabilities today in a series of attacks to execute remote commands against SMA1000 devices, and urged customers to install the hotfix immediately. The vulnerabilities affect the 6210, 7210, and 8200v models, while SMA 100 Series products and the SSL-VPN service running on SonicWall firewalls are not affected.

2026-09-02
3 min read
12 views
فريق تحرير certi.news
SonicWall Warns of Zero-Day Exploitation in SMA1000 Devices

On September 2, 2026, SonicWall warned of active exploitation of two zero-day vulnerabilities in SMA1000 secure remote access devices, confirming that attackers are chaining them to conduct attacks that enable remote command execution on affected devices. The company asked customers to install the latest hotfix release as soon as possible.

The first vulnerability, CVE-2026-83548, exists in the Appliance WorkPlace interface and is classified as a highly severe command injection flaw. The issue is associated with a server-side request forgery, or SSRF, weakness that can be used as part of the exploitation chain to gain command execution on the device.

The second vulnerability, CVE-2026-83549, exists in the Appliance Management Console. An attacker with administrative privileges can exploit it to execute arbitrary operating system commands on unpatched devices. According to SonicWall's warning, the ongoing exploitation combines the two vulnerabilities rather than treating each as a separate attack path.

Affected Devices and Response Measures

The SMA1000 6210, SMA1000 7210, and SMA1000 8200v models are affected by the two vulnerabilities, whether the devices are virtual or physical. The company explained that the SSL-VPN service running on SonicWall firewalls, as well as SMA 100 Series products, are not within the scope of the impact described in the warning.

In addition to installing the hotfix, SonicWall recommended that system administrators recreate the device image, change user and administrator passwords, and reset TOTP-based multi-factor authentication tokens if signs of compromise appear. However, the company has not yet published details about the ongoing attacks or a list of the indicators of compromise it identified during the investigation.

Why Does This Matter?

SMA1000 devices host remote access functions used by large institutions, government entities, and critical infrastructure organizations, making their compromise potentially more impactful than the compromise of a single device. According to Shadowserver data cited by the report, more than 400 SMA1000 devices are exposed on the internet, although some of these devices may already have received the patch.

In practice, installing the patch alone is not sufficient if indicators of compromise are present; SonicWall's recommendations indicate that the device, accounts, and authentication tokens should be treated as potentially compromised elements. Defense teams' ability to verify incidents remains relatively limited in the absence of an official indicator-of-compromise list from the company.

A Recurring Security Context

The incident follows the exploitation of two other vulnerabilities in SMA1000, CVE-2026-15409 and CVE-2026-15410, during July 2026 in attacks that continued for weeks and involved the installation of custom malware on affected VPN devices. The following month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs had begun actively exploiting the two vulnerabilities.

SonicWall also warned in December of another vulnerability in SMA1000, CVE-2025-40602, which was used with other vulnerabilities to obtain root privileges. The repeated exploitation means that administrators of the affected devices need to review patch status and access logs rather than simply wait for a new warning to appear.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news